Medium severity6.5NVD Advisory· Published Apr 9, 2026· Updated Apr 29, 2026
CVE-2026-5263
CVE-2026-5263
Description
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would accept them as valid.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/wolfSSL/wolfssl/pull/10048nvdIssue TrackingPatch
News mentions
0No linked articles in our index yet.